Getting Cyber Essentials Certified

1. Figuring Out What Needed Protecting

Before checking a single security setting, I needed a complete picture of everything connected to the business. I mapped out all our cloud apps and software—like Microsoft 365—alongside every piece of hardware touching corporate data. That meant accounting for every remote laptop, office desktop, firewall, switch, and server. Doing this up front ensured no hidden devices or forgotten software could sneak past the audit.

2. Finding the Gaps

With everything catalogued, I checked our setup against the official Cyber Essentials rules to see where we fell short. I audited our operating systems, checked whether our network hardware was running outdated firmware, and made sure all software in use was still actively supported by vendors.

I also dug into user accounts and logins. I cleaned up permissions so nobody had admin rights they didn't need, separated daily user accounts from administrator ones, and checked our login policies to ensure Multi-Factor Authentication (MFA) was turned on for everyone.

3. Fixing the Weak Spots

Spotting problems is the easy part; fixing them without interrupting everyone's workday is where the real effort lies. I methodically worked through our list of issues—updating firewall and switch firmware, retiring old equipment, and removing unapproved software.

To keep us secure long-term, I used tools like Microsoft Intune and Group Policy to automate our security rules. This made sure hard drives were encrypted automatically, screens locked when left unattended, and critical security patches were installed within 14 days of release. I brought every non-compliant device up to standard until the entire fleet passed checks.

4. Crossing the Finish Line

Once every device and system was ready, I gathered our evidence—such as policy settings and network layouts—and submitted the assessment through the IASME portal. I handled questions from the assessors directly, providing clear technical context so there was no unnecessary back-and-forth.

We passed on the first attempt. More importantly, the project left us with a much tighter security setup, zero outdated gear, and a straightforward routine that makes annual renewals easy to manage.